Vulnerability index

Browse CVEs

467 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.1 CVE-2021-22936 A vulnerability in Pulse Connect Secure before 9.1R12 could allow a threat actor to perform a cross-site script attack against an authenticated admin… Connect Secure 9.1+ Fix from $1,6002021-08-16 HIGH 7.2 CVE-2021-3198 By abusing the 'install rpm url' command, an attacker can escape the restricted clish shell on affected versions of Ivanti MobileIron Core. This issu… Mobileiron 11.1.0.0+ Fix from $1,9502021-07-22 HIGH 7.2 CVE-2021-3540 By abusing the 'install rpm info detail' command, an attacker can escape the restricted clish shell on affected versions of Ivanti MobileIron Core. T… Mobileiron 11.1.0.0+ Fix from $1,9502021-07-22 HIGH 8.8 CVE-2021-22908EPSS 69% A buffer overflow vulnerability exists in Windows File Resource Profiles in 9.X allows a remote authenticated user with privileges to browse SMB shar… Connect Secure Mitigation only Fix from $1,9502021-05-27 HIGH 8.8 CVE-2021-22894 KEVEPSS 41% A buffer overflow vulnerability exists in Pulse Connect Secure before 9.1R11.4 allows a remote authenticated attacker to execute arbitrary code as th… Connect Secure Mitigation only Fix from $1,9502021-05-27 HIGH 8.8 CVE-2021-22899 KEVEPSS 23% A command injection vulnerability exists in Pulse Connect Secure before 9.1R11.4 allows a remote authenticated attacker to perform remote code execut… Connect Secure Mitigation only Fix from $1,9502021-05-27 HIGH 7.2 CVE-2021-22900 KEVEPSS 14% A vulnerability allowed multiple unrestricted uploads in Pulse Connect Secure before 9.1R11.4 that could lead to an authenticated administrator to pe… Connect Secure after 9.1 Fix from $1,9502021-05-27 CRITICAL 10.0 CVE-2021-22893 KEVEPSS 47% Pulse Connect Secure 9.0R3/9.1R1 and higher is vulnerable to an authentication bypass vulnerability exposed by the Windows File Share Browser and Pul… Connect Secure Mitigation only Fix from $2,3002021-04-23 HIGH 8.8 CVE-2020-13769 LDMS/alert_log.aspx in Ivanti Endpoint Manager through 2020.1 allows SQL Injection via a /remotecontrolauth/api/device request. Endpoint Manager after 2020.1 Fix from $1,9502020-11-16 MEDIUM 5.4 CVE-2020-13773 Ivanti Endpoint Manager through 2020.1.1 allows XSS via /LDMS/frm_splitfrm.aspx, /LDMS/licensecheck.aspx, /LDMS/frm_splitcollapse.aspx, /LDMS/alert_l… Endpoint Manager after 2020.1.1 Fix from $1,6002020-11-16 MEDIUM 5.3 CVE-2020-13772 In /ldclient/ldprov.cgi in Ivanti Endpoint Manager through 2020.1.1, an attacker is able to disclose information about the server operating system, l… Endpoint Manager after 2020.1.1 Fix from $1,6002020-11-16 CRITICAL 9.9 CVE-2020-13774 An unrestricted file-upload issue in EditLaunchPadDialog.aspx in Ivanti Endpoint Manager 2019.1 and 2020.1 allows an authenticated attacker to gain r… Endpoint Manager Mitigation only Fix from $2,3002020-11-12 HIGH 7.8 CVE-2020-13770 Several services are accessing named pipes in Ivanti Endpoint Manager through 2020.1.1 with default or overly permissive security attributes; as thes… Endpoint Manager after 2020.1.1 Fix from $1,9502020-11-12 HIGH 7.8 CVE-2020-13771 Various components in Ivanti Endpoint Manager through 2020.1.1 rely on Windows search order when loading a (nonexistent) library file, allowing (unde… Endpoint Manager after 2020.1.1 Fix from $1,9502020-11-12 HIGH 7.2 CVE-2020-8260 KEVEPSS 96% A vulnerability in the Pulse Connect Secure < 9.1R9 admin web interface could allow an authenticated attacker to perform an arbitrary code execution … Connect Secure after 9.0 Fix from $1,9502020-10-28 MEDIUM 6.1 CVE-2020-8262 A vulnerability in the Pulse Connect Secure / Pulse Policy Secure below 9.1R9 could allow attackers to conduct Cross-Site Scripting (XSS) and Open Re… Connect Secure 9.1+ Fix from $1,6002020-10-28 HIGH 7.2 CVE-2020-15352 An XML external entity (XXE) vulnerability in Pulse Connect Secure (PCS) before 9.1R9 and Pulse Policy Secure (PPS) before 9.1R9 allows remote authen… Connect Secure after 9.0 Fix from $1,9502020-10-27 HIGH 7.2 CVE-2020-8243 KEVEPSS 91% A vulnerability in the Pulse Connect Secure < 9.1R8.2 admin web interface could allow an authenticated attacker to upload custom template to perform … Connect Secure after 9.0 Fix from $1,9502020-09-30 MEDIUM 6.1 CVE-2020-8238 A vulnerability in the authenticated user web interface of Pulse Connect Secure and Pulse Policy Secure < 9.1R8.2 could allow attackers to conduct Cr… Connect Secure after 9.0 Fix from $1,6002020-09-30 CRITICAL 9.8 CVE-2020-12441 Denial-of-Service (DoS) in Ivanti Service Manager HEAT Remote Control 7.4 due to a buffer overflow in the protocol parser of the ‘HEATRemoteService’ … Desktop\&server Management 2020.1+ Fix from $2,3002020-08-06 CRITICAL 9.8 CVE-2020-13793 Unsafe storage of AD credentials in Ivanti DSM netinst 5.1 due to a static, hard-coded encryption key. Dsm Netinst Mitigation only Fix from $2,3002020-08-06 MEDIUM 6.8 CVE-2020-8222 A path traversal vulnerability exists in Pulse Connect Secure <9.1R8 that allowed an authenticated attacker via the administrator web interface to pe… Connect Secure after 9.0 Fix from $1,6002020-07-30 HIGH 8.1 CVE-2020-8206 An improper authentication vulnerability exists in Pulse Connect Secure <9.1RB that allows an attacker with a users primary credentials to bypass the… Connect Secure after 9.0 Fix from $1,9502020-07-30 HIGH 7.2 CVE-2020-8218 KEVEPSS 32% A code injection vulnerability exists in Pulse Connect Secure <9.1R8 that allows an attacker to crafted a URI to perform an arbitrary code execution … Connect Secure after 9.0 Fix from $1,9502020-07-30 HIGH 7.2 CVE-2020-8219 An insufficient permission check vulnerability exists in Pulse Connect Secure <9.1R8 that allows an attacker to change the password of a full adminis… Connect Secure after 9.0 Fix from $1,9502020-07-30 MEDIUM 6.5 CVE-2020-8220 A denial of service vulnerability exists in Pulse Connect Secure <9.1R8 that allows an authenticated attacker to perform command injection via the ad… Connect Secure after 9.0 Fix from $1,6002020-07-30 MEDIUM 6.1 CVE-2020-8204 A cross site scripting (XSS) vulnerability exists in Pulse Connect Secure <9.1R5 on the PSAL Page. Connect Secure after 9.0 Fix from $1,6002020-07-30 MEDIUM 5.4 CVE-2020-8217 A cross site scripting (XSS) vulnerability in Pulse Connect Secure <9.1R8 allowed attackers to exploit in the URL used for Citrix ICA. Connect Secure after 9.0 Fix from $1,6002020-07-30 MEDIUM 5.5 CVE-2020-12880 An issue was discovered in Pulse Policy Secure (PPS) and Pulse Connect Secure (PCS) Virtual Appliance before 9.1R8. By manipulating a certain kernel … Connect Secure after 9.0 Fix from $1,6002020-07-27 HIGH 7.8 CVE-2019-17066 In Ivanti WorkSpace Control before 10.4.40.0, a user can elevate rights on the system by hijacking certain user registries. This is possible because … Workspace Control 10.4.40.0+ Fix from $1,9502020-05-18